TME LEGAL | DUBAI – RECHT KLAR

Safeguarding Personal Data – Penalties Await Financial Entities Violating Saudi Arabia’s Data Protection Laws

Safeguarding Personal Data – Penalties Await Financial Entities Violating Saudi Arabia’s Data Protection Laws


Impact and Compliance of Financial Entities Under the New Personal Data Protection Mandate


Saudi Arabia has taken a significant step towards safeguarding personal data by enacting the Personal Data Protection Law. With the exponential growth in digital transactions and data sharing, the protection of personal information has become a paramount concern. Financial entities deal with substantial amounts of sensitive customer data, making their compliance with the new law of utmost importance. To ensure data privacy and security, the Saudi Arabian authorities have implemented strict penalties for financial entities found in violation of the Personal Data Protection Law.


New PDPL Regime and its Impact on the Banking and Financial Services Sector


The Personal Data Protection Law was introduced in the Kingdom of Saudi Arabia to align the nation’s data protection standards with international best practices and to provide individuals with enhanced control over their personal information. The law encompasses various principles, including consent, purpose limitation, data accuracy, security, and accountability.


Saudi Arabia’s Personal Data Protection Law (PDPL) is safeguarding individuals’ privacy and imposing significant penalties on banks for non-compliance. Effective from September 14, 2023, the PDPL regulates the handling of personal data by entities operating within the Kingdom.


The PDPL draws inspiration from globally recognized data protection laws, such as the EU’s General Data Protection Regulation, and is guided by principles such as consent, transparency, lawfulness, and purpose limitation. This makes it relatively straightforward for most companies to comply. However, industries that extensively deal with personal data, such as the banking and financial services sector, may face additional requirements and the need to implement stricter controls, policies, and protocols.


Rigorous Penalties for Non-Compliance: From Fines to Revocation of Banking Licenses


Compliance obligations include ensuring the security, accuracy, and confidentiality of personal data, which may impact an organization’s IT infrastructure, systems, and policies. Data controllers must obtain explicit consent from individuals before processing their personal data unless specific exceptions apply. Additionally, companies are required to appoint a data protection officer, conduct data protection impact assessments, report data breaches, and obtain prior approval for cross-border data transfers.


Failure to comply with the PDPL can lead to severe consequences, including fines of up to SR3 million ($800,000) or imprisonment for up to two years. In exceptional cases or persistent non-compliance, the Saudi Central Bank (SAMA) reserves the right to suspend or revoke banking licenses.


Although the precise process for reporting and handling non-compliance cases is still being defined, it is likely that individuals will be directed to the Ministry of Commerce, which will establish an official reporting and complaint handling mechanism over time.

Share:

More Posts

Amendments of Family- and Inheritance Law in the UAE: Federal Personal Status Law No. 41 of 2024

Federal Decree-Law No. 41 of 2024 represents a significant advancement in the UAE’s personal status legal framework. This legislation introduces significant changes to family law, marriage, divorce, custody, and inheritance, reflecting the UAE’s commitment to modernizing its legal system while balancing the interests of both citizens and expatriates. The primary objective of the new law is to enhance family stability, ensure procedural efficiency, and align legal principles with contemporary societal needs.

New Digital Technologies Enhance Tax Compliance Amid Surge in FTA Inspection Visits

The United Arab Emirates (UAE) has made significant progress in digitizing its tax administration in recent years. The Federal Tax Authority (FTA) has intensified its inspection efforts to ensure tax compliance, particularly concerning Value Added Tax (VAT) and the recently introduced Corporate Tax.

Digital technologies, including Artificial Intelligence (AI), Blockchain, and automation software, are playing an increasingly vital role in helping businesses meet FTA requirements efficiently and mitigate compliance risks.

New Legal Framework for the Regulation of Pharmaceutical Products in the UAE

New Legal Framework for the Regulation of Pharmaceutical Products in the UAE

Federal Decree-Law No. 38 of 2024, effective from January 2, 2025, introduces comprehensive reforms to the United Arab Emirates‘ pharmaceutical sector, superseding Federal Law No. 8 of 2019. This legislation aims to enhance regulatory oversight, promote innovation, and position the UAE as a global hub for pharmaceutical and medical industries.

The UAE Advances as a Global AI Powerhouse

Through a combination of strategic investment, regulatory foresight, and partnerships with top technology firms, the country is positioning itself as a global AI powerhouse. With AI expected to be a major driver of economic growth, the UAE is well on its way to becoming a world leader in artificial intelligence and digital transformation.